VDB
GCVE-VVD-MAGEIA-2020-206
GCVE-VVD-MAGEIA-2020-206
Advisory Published
Updated roundcubemail packages fix security vulnerabilities:
- Cross-Site Scripting (XSS) via malicious HTML content
(CVE-2020-12625)
- CSRF attack can cause an authenticated user to be logged out
(CEV-2020-12626)
- Remote code execution via crafted config options
- Path traversal vulnerability allowing local file inclusion via
crafted 'plugins' option
Affected Products
| Vendor | Product | Versions | Platforms |
|---|---|---|---|
| Mageia | llvm | 0 (affected), 8.0.0-1.1.mga7 (unaffected) | — |
| Mageia | roundcubemail | 0 (affected), 1.3.11-1.mga7 (unaffected), 0 (affected), 1.3.11-1.mga7 (unaffected) | — |
| Mageia | rust | 0 (affected), 1.43.1-1.mga7 (unaffected) | — |
Aliases
Transitive aliases
References
Browse GCVE Records
100 records in the GCVE database · Updated April 16, 2026
No matching records found.
Explore Further
Investigate this vulnerability in the interactive console or download the raw GCVE record.